ALPR Audit Watch
Minnesota requires an independent audit of every license plate reader program every two years. We track who runs ALPRs, who audits them, and what those audits find.
Most of them find nothing. A small number of auditors produce most of the reports, and the reports look alike.
118
Agencies tracked
116 on the BCA list
61
No audit located
of 118 agencies
68
Audits reviewed
56 with zero findings
13
Distinct auditors
across every audit found
What the law requires
Under Minn. Stat. § 13.824, subdivision 6, any law enforcement agency operating an automated license plate reader must arrange an independent, biennial audit of its ALPR records. The audit has to confirm that the data is properly classified, that it is being used only as the statute allows, that it is destroyed on schedule, and that every query was authorized.
Results go to the Commissioner of Administration, the chairs and ranking minority members of the relevant legislative committees, and the Legislative Commission on Data Practices, within 30 days. If an audit finds substantial noncompliance, the commissioner may order the agency’s readers shut off until it complies.
Separately, ALPR data unrelated to an active investigation must be destroyed within 60 days, and agencies must report each reader to the BCA within ten days of installation.
The pattern
Audit Requirements and Audit Mills
The statute does not define who counts as an independent auditor, what the audit must test, or what the report must contain. In practice a handful of firms and consortiums produce most of the reports in Minnesota, several of them run by former law enforcement officials, and several of them auditing the same member agencies that fund them.
A real audit almost always turns something up. Records get held past the 60-day deletion window, a reader goes unreported to the BCA, a log of use never gets maintained, a query lacks documented authorization. Findings are the visible evidence that someone actually looked. An auditor who reports them is doing the job the legislature described.
A template that clears every agency it touches is a different thing. When the same firm files the same checklist year after year and never records a discrepancy, the audit stops being an inspection and becomes a stamp. That satisfies the letter of the statute while defeating its purpose, which was to put an independent set of eyes on a surveillance system the public cannot see.
Of the 68 audits we have read in full, 56 recorded zero findings (82% of them). The reports run from two pages to nine. Most are checklists: a statute-by-statute table, a policy review, and a sentence stating that no discrepancies were noted.
The audits that do dig in find real problems. The one auditor who tested the live platform found that Flock data exports generate no audit-trail entry at all, a flaw that undercuts the 60-day deletion rule the audit exists to verify, and one that applies to every agency running the same system. Nobody else caught it.
How to read this tracker
Green marks an auditor doing real work: findings on the record, and testing that goes past the paperwork.
Red marks rubber-stamp signals: superficial audits, conflicts of interest, or clean sheet after clean sheet.
When an audit does record findings, we grade each one by how much it actually matters:
- Systemic
- The audit caught a flaw in the platform itself, so fixing it fixes the system for every agency that uses it. The benchmark: exported plate data that escaped the 60-day deletion rule with no audit trail.
- Material
- The auditor put in the work and surfaced a significant problem: data kept too long, unlogged queries, no breach policy, unreported cameras.
- Superficial
- A trivial note recorded for the sake of having something to show. Paperwork nits, wording tweaks. These findings are noted, but do not count towards substantial work or accountability building by the auditors.
- Ghost finding
- A problem the audit describes in its own text but never records. It does not change the official count, but it counts against the auditor, because it proves they knew.
Auditing the Auditors
By Auditor
| Auditor | Verdict | Agencies | Audits read | Zero findings | Real findings | Flags |
|---|---|---|---|---|---|---|
| Minnesota Security Consortium (MNSec) Government consortium | Audit-mill signals | 18 | 20 | 17/20 (85%) | 3 | Tested the system, not the paperworkGhost findingsAudits its own membersLaw enforcement background |
| Lynn Lembcke Consulting Private consultant | Structural flag | 17 | 17 | 15/17 (88%) | 2 | Law enforcement background |
| LOGIS Government consortium | Audit-mill signals | 10 | 13 | 13/13 (100%) | 0 | Never recorded a findingAudits its own members |
| LEADS Consulting Private consultant | Audit-mill signals | 4 | 4 | 4/4 (100%) | 0 | Tested the system, not the paperworkGhost findingsNever recorded a findingLaw enforcement background |
| Rampart Audit LLC Private consultant | Doing the work | 3 | 3 | 2/3 (67%) | 1 | Found a systemic flawTested the system, not the paperworkGhost findings |
| Axtell Group Private consultant | Audit-mill signals | 2 | 2 | 1/2 (50%) | 1 | Real findings in most auditsAudits its own membersLaw enforcement background |
| In-house / City Auditor In-house / city auditor | Doing the work | 2 | 2 | 0/2 (0%) | 7 +2 superficial | Tested the system, not the paperworkReal findings in most audits |
| Office of the State Auditor State oversight office | Doing the work | 2 | 2 | 1/2 (50%) | 1 | Real findings in most audits |
| Backbone Consultants Private consultant | Too few audits read | 1 | 1 | 1/1 (100%) | 0 | — |
| FRSecure Private consultant | Too few audits read | 1 | 1 | 1/1 (100%) | 0 | — |
| Office of the State Auditor (OSA) Other | Audit-mill signals | 1 | 1 | 1/1 (100%) | 0 | Ghost findings |
| Other Other | Doing the work | 1 | 1 | 0/1 (0%) | 3 | Real findings in most audits |
| Wildcard Private consultant | Doing the work | 1 | 1 | 0/1 (0%) | 2 +1 superficial | Real findings in most audits |
Flags and rates are computed only over audits FinePrint has read in full, so unverified leads cannot flatter or distort an auditor’s record.
The roster
By Agency
Seeded from the BCA’s published list of agencies using license plate readers, plus agencies we have documented operating ALPRs that the BCA list does not name.
Showing 118 of 118
By filing year
Undated
2 audits
- Duluth Police DepartmentFRSecureNo findingsChecklist
- Golden Valley Police DepartmentAuditor unconfirmedNot yet reviewed
2026
20 audits
- Belle Plaine Police DepartmentLynn Lembcke ConsultingNo findingsSubstantive
- Corcoran Police DepartmentMinnesota Security Consortium (MNSec)No findingsChecklist
- Hopkins Police DepartmentMinnesota Security Consortium (MNSec)No findingsChecklist
- Maplewood Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- Minneapolis Police DepartmentIn-house / City Auditor2 findingsMaterialSuperficialSubstantive
- Minnetonka Police DepartmentLOGISNo findingsChecklist
- Minnetrista Police DepartmentMinnesota Security Consortium (MNSec)No findingsChecklist
- Mounds View Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- New Hope Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- New Prague Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- Richfield Police DepartmentMinnesota Security Consortium (MNSec)No findingsChecklist
- Robbinsdale Police DepartmentMinnesota Security Consortium (MNSec)No findingsChecklist
- Roseville Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- Shakopee Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- South Lake Minnetonka Police DepartmentMinnesota Security Consortium (MNSec)No findingsChecklist
- St. Cloud Police DepartmentRampart Audit LLCNo findingsSubstantive
- St. Francis Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- West Saint Paul Police DepartmentMinnesota Security Consortium (MNSec)No findingsChecklist
- Woodbury Public SafetyMinnesota Security Consortium (MNSec)No findingsChecklist
- Wyoming Police DepartmentMinnesota Security Consortium (MNSec)No findingsDeep / technical
2025
30 audits
- Anoka County Sheriff's OfficeLynn Lembcke ConsultingNo findingsChecklist
- Anoka Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- Blaine Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- Bloomington Police DepartmentLOGISNo findingsSubstantive
- Brooklyn Center Police DepartmentMinnesota Security Consortium (MNSec)1 findingMaterialChecklist
- Champlin Police DepartmentMinnesota Security Consortium (MNSec)1 findingMaterialSubstantive
- Champlin Police DepartmentMinnesota Security Consortium (MNSec)1 findingMaterialSubstantive
- Columbia Heights Police DepartmentLynn Lembcke Consulting1 findingMaterialChecklist
- Coon Rapids Police DepartmentLOGISNo findingsSubstantive
- Deephaven Police DepartmentAxtell Group1 findingMaterialSubstantive
- Eden Prairie Police DepartmentLOGISNo findingsSubstantive
- Edina Police DepartmentMinnesota Security Consortium (MNSec)No findingsChecklist
- Faribault Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- Grand Rapids Police DepartmentRampart Audit LLCNo findingsGhost findingSubstantive
- Hennepin County Sheriff's OfficeMinnesota Security Consortium (MNSec)No findingsDeep / technical
- Hennepin County Sheriff's OfficeMinnesota Security Consortium (MNSec)No findingsDeep / technical
- Minneapolis Police DepartmentWildcard3 findings2 MaterialSuperficialSubstantive
- Oakdale Police DepartmentMinnesota Security Consortium (MNSec)No findingsGhost findingChecklist
- Olmsted County Sheriff's OfficeMinnesota Security Consortium (MNSec)No findingsGhost findingChecklist
- Orono Police DepartmentMinnesota Security Consortium (MNSec)No findingsGhost findingChecklist
- Paul Bunyan Drug Task ForceRampart Audit LLC1 findingSystemicDeep / technical
- Plymouth Police DepartmentLynn Lembcke Consulting1 findingMaterialChecklist
- Sartell Police DepartmentAxtell GroupNo findingsSubstantive
- South St. Paul Police DepartmentLOGISNo findingsSubstantive
- St. Louis Park Police DepartmentLOGISNo findingsSubstantive
- St. Paul Police DepartmentLOGISNo findingsSubstantive
- University of Minnesota Police DepartmentMinnesota Security Consortium (MNSec)No findingsChecklist
- Waseca Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
- West Hennepin Public SafetyLynn Lembcke ConsultingNo findingsChecklist
- Willmar Police DepartmentLynn Lembcke ConsultingNo findingsChecklist
2024
3 audits
- Maple Grove Police DepartmentLOGISNo findingsSubstantive
- Minnesota State PatrolMinnesota Security Consortium (MNSec)No findingsDeep / technical
- Rochester Police DepartmentLOGISNo findingsSubstantive
2023
1 audit
- Bloomington Police DepartmentLOGISNo findingsSubstantive
2022
2 audits
- Minnesota State PatrolOffice of the State Auditor (OSA)No findingsGhost findingSubstantive
- Rochester Police DepartmentLOGISNo findingsSubstantive
2020
4 audits
- Minnesota State PatrolLEADS ConsultingNo findingsDeep / technical
- Olmsted County Sheriff's OfficeOffice of the State Auditor1 findingMaterialSubstantive
- Rochester Police DepartmentOffice of the State AuditorNo findingsSubstantive
- Shakopee Police DepartmentLEADS ConsultingNo findingsDeep / technical
2019
3 audits
- Crystal Police DepartmentLOGISNo findingsSubstantive
- MSP Airport PoliceIn-house / City Auditor7 findings6 MaterialSuperficialDeep / technical
- Rochester Police DepartmentBackbone ConsultantsNo findingsChecklist
2018
2 audits
- Maple Grove Police DepartmentLOGISNo findingsSubstantive
- Moorhead Police DepartmentLEADS ConsultingNo findingsDeep / technical
2017
2 audits
- Brooklyn Park Police DepartmentLEADS ConsultingNo findingsGhost findingDeep / technical
- Ramsey County Sheriff's OfficeOther3 findings3 MaterialSubstantive
Findings are shown in green because a recorded finding is evidence the auditor looked. A clean sheet is shown in red.
Method and sources
- —The agency roster is seeded from the BCA’s published list of agencies using LPRs. Agencies we document elsewhere are added and flagged as not listed.
- —Audit reports come from the Legislative Reference Library’s mandated-reports collection, from agency records requests, and from Department of Administration filings. Every reviewed audit links to its primary source.
- —Findings counts, flags, and clean rates are computed only over audits FinePrint has read in full.
- —Audit depth is a FinePrint editorial assessment: checklist (paperwork only), substantive (sampled records or tested some controls), deep (tested the live system, logs, or exports).
- —A ghost finding is a problem an audit describes in its own narrative but never records as a finding: found, sometimes fixed mid-audit, and left off the record. Ghost findings do not change an audit’s official findings count, but they are flagged on the audit and count against the auditor.
- —Every individual finding is categorized by FinePrint into one of three tiers: systemic (a major structural flaw in the platform or program itself, weakening privacy protections beyond the audited agency), material (a substantive compliance failure with real privacy impact at that agency), and superficial (anything that does not affect privacy or mass surveillance in a real way). Auditors are credited for systemic and material findings; a record of only superficial ones is treated as a rubber-stamp signal.
- —Next-expected year is the most recent located audit plus two, per the biennial requirement.
- —Flags describe what the filed reports contain and who wrote them. They are not an allegation that any audit was fraudulent or that any agency is out of compliance.
Know of an ALPR program that isn’t here?
We are looking for audits we have not found, agencies running readers that the BCA list does not name, and any audit that actually turned something up. If you have a report, a records response, or a lead, we want it.
Send a tip →Related
For policymakers
How to fix the ALPR audit: seven changes to Minn. Stat. § 13.824 that would turn the biennial audit from a rubber stamp into real oversight, backed by what this tracker has found.
FlockFeed
The companion tracker: Minnesota’s Flock Safety transparency portals, logged change by change as cameras are added, data sharing expands, and departments go dark.